1. Who controls the data
The operating legal entity identified on the PinX Golf invoice, receipt or business contact information acts as the data controller for customer commerce data. Certain service providers process data to provide identity, payment or infrastructure services.
2. Data we use
PinX may process account identifiers, email and contact information, delivery addresses, order and return history, saved products, rewards activity, reviews, support conversations, notification preferences, vendor access records, audit events and security logs. Payment records include transaction status and provider references, not your M-Pesa PIN.
3. Why we use it
Data is used to create and perform orders, authenticate accounts, deliver goods, process returns, operate support, protect the service, maintain auditability, communicate requested account information and, where you opt in, send marketing communications. Marketing preferences default off in the current implementation.
4. Service providers
PinX uses Clerk for production identity and Safaricom Daraja for M-Pesa workflows when enabled. PostgreSQL, Garage object storage, the application worker and Caddy are designed for client-controlled hosting. Providers should receive only the information required for their service.
5. Retention
Personal data should be kept only for as long as needed for the purpose collected, transaction and accounting records, dispute handling, security, fraud prevention and other lawful obligations. Operational backups are protected and follow the documented retention and recovery process.
6. Your rights
Subject to applicable law, you may request information about use of your personal data, access data held about you, object to certain processing, and request correction or deletion where the legal conditions are met. Marketing consent can be changed in the customer notification preferences.
7. Security and access
Customer and vendor APIs are role scoped, vendor administrative actions are audited, production authentication uses Clerk, infrastructure secrets are not intended to be stored in audit or notification records, and production data services remain behind the application ingress.
8. International processing
Where an external provider processes personal data outside Kenya, the operating entity should ensure the transfer and provider relationship use appropriate safeguards required by applicable data protection law.
9. Requests and complaints
Use the customer support workflow or the official business contact shown on your order documentation for privacy requests. You may also have the right to raise a complaint with the Office of the Data Protection Commissioner in Kenya.